• DocumentCode
    3180437
  • Title

    A rate limiting mechanism for defending against flooding based distributed denial of service attack

  • Author

    Patil, Rachana Yogesh ; Ragha, Lata

  • Author_Institution
    Dept. of Comput. Eng., A.C. Patil Coll. of Eng., Khargher, India
  • fYear
    2011
  • fDate
    11-14 Dec. 2011
  • Firstpage
    182
  • Lastpage
    186
  • Abstract
    The distributed denial of service attack is a major threat to current internet security. One of the most threatening type is flooding based DDoS attack. In this paper we have proposed a defense mechanism for flooding based DDoS attack based on the concept of rate limiting the attack traffic The propose defense framework consist of three major components, detection, IP traceback and bandwidth control component. The proposed defense system is a distributed mechanism because it is deployed on all edge routers of the network. Our defense algorithm that is bandwidth control algorithm mainly tries to keep the server load within the maximum and minimum server load limits. The bandwidth control component at the victim end set up rate limits according to server load and source end traffic rate with the help of bandwidth control component at source end. The proposed rate limiting scheme will penalize the different attackers based on their rate limits and server load. The rate limit value for each attacker router is calculated dynamically. The victim end defense system decrease the rate limit exponentially and increase it linearly based on the attack traffic rate.
  • Keywords
    IP networks; computer network security; IP traceback; attack traffic rate; bandwidth control algorithm; flooding based DDoS attack; flooding based Distributed Denial of Service attack; internet security; maximum server load limit; minimum server load limit; network edge router; rate limiting mechanism; source end traffic rate; victim end set up rate limit; Bandwidth; Computer crime; Floods; IP networks; Image edge detection; Limiting; Servers; Distributed denial of service (DDoS) attack; Flooding; Ip traceback; Rate limiting;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information and Communication Technologies (WICT), 2011 World Congress on
  • Conference_Location
    Mumbai
  • Print_ISBN
    978-1-4673-0127-5
  • Type

    conf

  • DOI
    10.1109/WICT.2011.6141240
  • Filename
    6141240